STARBUCKS CORPORATION
ent_019fa5cca16bcfe129222a86d92f4fb2
Disclosures
6
Leak Site · State AG · 4 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
889
nationwide · State AG IN
Leak-site claims
2
unverified actor claims
Identity resolution
- Canonical name
- STARBUCKS CORPORATION
- Normalized
- starbucks— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- OQSJ1DU9TAOC51A47K68
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- starbucks.com
Disclosure history (6)newest first
- GLOBALLeak Siteas victim2026-05-21
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
- GLOBALLeak Siteas victim2026-04-01
StarBucks Failed to reach out to us and didn't pay even $500,000 when we know they can afford it. It's not even that much we were asking for. Since you didn't contact is no negotiations and this is now in the hands of cybercriminals. This is a warning to all companies if you see yourself posted here to reach us. This is the only ammount we have on are servers due to migrating dmca and ignore abuse infrastructure. They were breached on 04/01/2026 and they know they were breached because they closed the s3 bucket starbucks-prod.
- 🦞Maine State AGas victim2026-03-12
Starbucks discovered Feb 6, 2026 that an external actor accessed Partner Central employee accounts via credentials stolen through phishing sites impersonating the portal (Jan 19–Feb 11, 2026). Exposed data: names, SSNs, DOBs, financial account/routing numbers. 889 total affected; 5 Maine residents. Law enforcement notified; access controls strengthened; 24-month Experian IdentityWorks offered.
- ⛰️New Hampshire State AGas victim2026-03-12
Starbucks Corporation notified the New Hampshire Attorney General on March 12, 2026, of a security breach affecting 4 NH residents. Starbucks became aware on Feb 6, 2026, that an unauthorized third party accessed employee accounts via phishing (impersonating Partner Central websites). Impacted data included names, SSNs, DOBs, and financial account/routing numbers. Starbucks reset credentials, engaged experts, notified law enforcement, and offered 24 months of credit monitoring.
- 🏎️Indiana State AGas victim2026-03-10
Starbucks Corp dba Starbucks Coffee Company reported a data breach to the Indiana Attorney General. The breach occurred on 2026-02-06 and was reported on 2026-03-10. 25 Indiana residents were affected. 889 individuals affected in total.
- 🏎️Indiana State AGas victim2026-03-10
Starbucks Corp dba Starbucks Coffee Company reported a data breach to the Indiana Attorney General. The breach occurred on 2026-02-06 and was reported on 2026-03-10. 25 Indiana residents were affected. 889 individuals affected in total.